Blog · 8 min read
6 Steps to a Procurement Ready VPAT Template Vendors Can Defend

A VPAT is the template vendors use to create an Accessibility Conformance Report, the document that shows how a product meets accessibility standards. Completing one means choosing the edition that matches the buyer’s required standard, then filling in the Remarks column with real test evidence. Once that report is done, procurement teams can use it to compare products fairly and make an informed purchasing decision.
TL;DR:
- Use the VPAT edition that matches the buyer’s requirement and ensure it is the current version to prevent rejection due to outdated standards.
- Complete all relevant tables thoroughly with specific, evidence-backed remarks to avoid vague or missing documentation that weakens credibility.
- Include test logs, screenshots, and remediation records with dates to substantiate claims and demonstrate ongoing accessibility improvements.
- Pair automated accessibility scans with manual testing to identify issues like keyboard traps and accurate alt text, citing both in the ACR.
- Keep official guidance sources handy and document adherence to standards such as Section 508, WCAG, or EN 301 549 for regulatory compliance and reviewer trust.
Table of Contents
- What a VPAT and ACR actually are
- Which VPAT edition and version should you use?
- Step-by-step: completing an ACR using the VPAT
- Common mistakes and a quick quality checklist
- What running scans and drafting remarks actually teaches you
- How AccessWiser supports your VPAT and ACR preparation
- Official templates and guidance worth bookmarking
- Sources
- FAQ
What a VPAT and ACR actually are
A VPAT is a blank template. Once a vendor fills it in with product details, testing methods, and conformance findings, the completed document becomes an Accessibility Conformance Report, or ACR. Procurement teams rely on the ACR because it gives them one consistent format to compare accessibility claims across different vendors and products, according to Section508.
The template maps to specific accessibility standards, and different VPAT editions reference different ones:
- Revised Section 508, the technical standard for information and communication technology used by federal agencies
- WCAG 2.x, the Web Content Accessibility Guidelines that Section 508 itself incorporates for web and software content
- EN 301 549, the European standard referenced by the EU edition of the VPAT
There is no formal certification process behind a VPAT. No government body or standards organization audits and stamps a completed ACR as accurate. Its credibility rests entirely on how well the vendor documents its testing methods and backs up each finding with real evidence, a point echoed in guidance on interpreting the VPAT.
Which VPAT edition and version should you use?
The Information Technology Industry Council publishes four VPAT editions, and picking the wrong one is one of the fastest ways to produce an ACR that a buyer rejects outright.
- 508 edition: built for Revised Section 508, the standard federal agencies require
- EU edition: built for EN 301 549, used across European procurement
- WCAG edition: built for organizations reporting against WCAG alone, without a regulatory framework attached
- INT edition: combines 508, EN 301 549, and WCAG into one document for vendors selling across multiple markets
Version matters as much as edition. ITI updates the VPAT periodically, and an outdated template can reference success criteria that no longer match current standards or omit fields reviewers now expect. The decision rule is simple: match the edition to what the contract or solicitation actually asks for, and confirm you are working from the current version before you start filling in tables. When U.S. federal buyers are involved, the 508 or INT edition is typically the expected choice, per Section508.gov’s how-to guide.
Step-by-step: completing an ACR using the VPAT
Filling out the template is a sequence, not a single sitting. Each step builds the evidence trail that gives your ACR weight with reviewers.
- Download the official template and record its version. Note the exact VPAT edition and version number on the title page, since reviewers will check that it matches the contract requirement.
- Complete the title page and product description. Include the product name, version, contact information, and a plain description of what the product does and how it’s used.
- Document your evaluation methods. List whether you used automated scanning, manual testing, assistive technology testing, or user testing with people who have disabilities, and link each method to dated evidence you can produce if asked.
- Fill in the Success Criteria tables. Complete Level A and AA rows fully; AAA is optional. If the contract requires Revised Section 508, complete those tables too.
- Assign conformance levels and write specific remarks. Use only the permitted levels (Supports, Partially Supports, Does Not Support, Not Applicable, Not Evaluated), and for anything short of full support, explain exactly what fails and why in the Remarks column.
- Assemble your supporting attachments. Keep test logs, screenshots, and remediation trackers with dates attached, since a Remarks entry without evidence behind it carries little weight.
Pro Tip: Write your Remarks column as if a stranger will need to verify your claim without asking you a follow-up question. Name the test method, the date, and the specific barrier found.
Following Section508.gov’s how-to sequence in order keeps the whole document consistent, which matters more than it sounds. A reviewer who spots one sloppy table tends to scrutinize every other table more closely.
Common mistakes and a quick quality checklist
Before you submit an ACR, run it against a short list of the same checks procurement reviewers use.
- Is the VPAT edition and version correct for the buyer’s stated requirement?
- Are all applicable tables completed, not just the ones that were easy to fill in?
- Does every row list an explicit evaluation method rather than an assumption?
- Does every Remarks entry that isn’t full support include evidence and a next step?
- Are dated artifacts, such as scan logs or tickets, available to back up each claim?
One of the most common weaknesses reviewers flag in an ACR is an empty or vague Remarks column, which guidance on interpreting the VPAT treats as a high-risk error because it leaves the buyer with no way to judge whether the claim is credible. Other frequent problems include marking “Supports” with no evidence attached, submitting on an outdated template version, defaulting to “Not Evaluated” across too many rows instead of doing the testing, and remediation plans that promise fixes without dates or specifics.
Procurement teams typically use the ACR during market research, comparing multiple vendors’ documents side by side before a purchase decision is made. A thin or evasive ACR can knock a product out of consideration even when a competitor’s product has similar gaps but better documentation.
What running scans and drafting remarks actually teaches you
Automated scans catch a meaningful share of accessibility problems quickly, but they miss issues that only surface through manual review, like whether a keyboard trap makes a form unusable or whether an alt text description actually conveys the image’s purpose. The strongest ACRs pair automated findings with targeted manual checks and cite both.

Dated scan records and linked remediation tickets do more work than most vendors expect. They turn a vague claim like “we’re working on this” into a Remarks entry a reviewer can actually trust, because it points to a specific date, a specific fix, and a specific person accountable for it.
Treat the ACR less like paperwork and more like a signal. A well-documented report, even one that admits a few gaps, tends to read as more trustworthy than a spotless one with no evidence behind it. That transparency is often what separates a vendor procurement teams feel confident choosing from one they pass over.
— The AccessWiser Team
How AccessWiser supports your VPAT and ACR preparation
Building the evidence base for an ACR is the hardest part of the process, and it’s exactly where AccessWiser fits in. Our scans check a website against WCAG 2.2 AA success criteria, mapping to related accessibility standards, and provide guidance to help fix issues in your code.
That combination gives you a documented, dated foundation for your Remarks column instead of a blank field you have to guess your way through. Our accessibility statement tools keep a dated record of scans and fixes, so when a reviewer asks for evidence behind a claim, you have it.
A practical workflow: run a starter scan through our solutions, export the findings your development team needs to act on, then review remediation progress together before you transfer results into your VPAT tables. Check our pricing page to find the plan that fits your site’s size and scan needs.

Official templates and guidance worth bookmarking
Cite the exact VPAT edition and version you used inside your ACR, and keep these sources on hand while you work:
- Section508 for baseline definitions and federal expectations
- Section508 for the full completion sequence
- The Access Board’s Revised Section 508 final rule for the regulatory standards behind the tables
- A third-party overview of ADA website expectations for background on how conformance levels connect to broader compliance obligations
Sources
- Accessibility Conformance Report/Voluntary Product Accessibility Template (VPAT®) Frequently Asked Questions (FAQ)
- How to Create an Accessibility Conformance Report Using A Voluntary Product Accessibility Template (VPAT®)
- Information and Communication Technology (ICT) Standards and Guidelines—Final rule (Access Board)
FAQ
What is a VPAT template?
A VPAT template is a standardized document vendors use to report how their product conforms to accessibility standards such as Revised Section 508, WCAG, or EN 301 549. Once completed, it becomes an Accessibility Conformance Report, according to Section508.gov.
How do I create a VPAT?
You download the official template edition that matches your buyer’s required standard, fill in the title page and product description, document your evaluation methods, and complete the applicable success criteria tables with specific, evidence-backed remarks. Section508.gov’s how-to guide walks through each step in order.
Who fills out a VPAT?
The vendor or manufacturer of the product typically completes the VPAT, since they are the ones with access to the product, its code, and its testing results. Larger organizations often assign this to a compliance officer or developer working alongside accessibility testers.
Is VPAT the same as WCAG?
No. WCAG is a set of accessibility guidelines, while a VPAT is the template vendors use to report conformance against standards that may include WCAG, Revised Section 508, or EN 301 549. The completed VPAT, called an ACR, is where those WCAG criteria get evaluated and documented.
Recommended
Articles on this blog are general information about web accessibility, not legal advice. Laws change and their application depends on your specific situation — for decisions with legal consequences, consult a qualified legal professional.
Articles on this blog are general information about web accessibility, not legal advice. Laws change and their application depends on your specific situation — for decisions with legal consequences, consult a qualified legal professional.